LIVE · cybersecurity feed
Live wire
Australia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Vulnerability Gap: Why Discovery Is Outrunning RepairCISA’s logging guidance works beyond government
ai

Identity Everywhere: Bringing Infrastructure Identity to Agentic IT

Segmentation limits attacker movement, contains AI-era threats, and strengthens cyber resilience with Zero Trust.

zeroday.news ·

Cisco and Teleport have announced a strategic partnership focused on integrating their technologies, licensing agreements, and a significant investment from Cisco, which is now Teleport's largest strategic investor. The collaboration aims to introduce a new security paradigm called "Infrastructure Identity," designed to provide a cryptographic foundation for secure identity across all human and machine actions within an enterprise's infrastructure.

The initiative addresses the growing complexity of modern identity management, particularly with the rise of automated workloads and AI agents that interact with critical systems. The traditional model, which often relies on fragmented, credential-based workflows and standing access, is deemed insufficient for an environment where non-human actors increasingly touch infrastructure. This approach often leads to security gaps, as operators may bypass approved, slower processes, creating unmanaged access points and leaving durable secrets exposed.

Infrastructure Identity proposes a shift from credential custody to identity-native access. The core principle is to eliminate anonymous computing in critical infrastructure by establishing trust for every actor and issuing privilege only for specific tasks, with access expiring once the task is complete. This model replaces static credentials and standing access with short-lived cryptographic identities and permissions, ensuring accountability without compromising operational speed.

The partnership will initially focus on privileged access for network and infrastructure administrators. For example, an engineer requiring access for maintenance would verify their identity and request only the necessary access for that specific task. Teleport would then broker and record the session, with the privilege expiring at the end of the access window, preventing the engineer from ever possessing a reusable credential that outlives the task. Cisco will contribute infrastructure and network context to enhance the utility and enforceability of this secure access path.

The companies state that this approach offers several benefits. Network and infrastructure teams will gain faster access to authorized resources without managing secrets or using outdated access methods. Security teams will have improved context to trace access decisions and sessions, aiding incident reconstruction and containment. AI teams can integrate autonomous agents into the same governance model from the outset, ensuring agents receive only the privilege required for their tasks, with every action attributable.

The need for Infrastructure Identity is amplified by the acceleration of machine actors and autonomous agents due to AI, which can quickly exploit identity gaps. The implications extend beyond software, as compromised or overprivileged actors in physical AI systems, such as robots or industrial controls, could affect the physical world before human intervention is possible. Therefore, Infrastructure Identity is presented not just as an access-control solution but as a foundation for operational resilience.

The collaboration leverages Cisco's position at the nexus of enterprise connections, providing network visibility, and Teleport's expertise in replacing secret-based access with short-lived, identity-native access that generates clear session records. This combined capability aims to bring identity context closer to where actions occur.

Looking ahead, the companies anticipate that the next decade of infrastructure will be characterized by a significant increase in autonomous software and physical AI acting on behalf of humans. They argue that trust in this environment cannot depend on shareable or persistent credentials but must be continuously established and tied directly to actions. The vision for Infrastructure Identity is to ensure no anonymous computing, no unmanaged privilege, and no forced trade-off between stronger security and operational speed, ultimately leading to an identity-aware network that extends actor context beyond IP addresses for enhanced visibility and policy enforcement.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

When the Algorithm Fires You: Uber Faces €825M Fine

Uber faces an €825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or cookie consent. The regulator imposed an 825 million euro penalty, roughly $964 million, over […]

ai

Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation

TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation. The post Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation appeared first on SecurityWeek.

security

Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice

Joshua Culver, aka “Maverick Young,” is accused of imitating the head of the NSA’s Tailored Access Operations unit during a time it wasn’t called that. The post Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice appeared first on CyberScoop.

ddos

Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack

Norway ’s shared government infrastructure suffered a third DDoS attack, disrupting digital services but showing no signs of data compromise. Norway ‘s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupted services used by citizens, businesses and public agencies. The incident began at 03:38 CEST on Monday, August 24, […]

security

Water sector passes, government sector fails attempts to spot and halt simulated CISA attack

Agency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further. The post Water sector passes, government sector fails attempts to spot and halt simulated CISA attack appeared first on CyberScoop.

patch

You could've applied all 1,449 Oracle patches and still been hit by this attack

Attackers now ready to exploit how things work, rather than just break them, says Oracle support expert